PS-9: Position Descriptions

PS-09 requires you to document security and privacy responsibilities directly inside every organizational position description.

Quick-reference card

FieldValue
Control IDPS-09
Control NamePosition Descriptions
FrameworkNIST SP 800-53 Revision 5
Control FamilyPersonnel Security
BaselinesLOW MODERATE HIGH
RelevanceOrganization (First Party and Third Party)
Risk SeverityLow

What this control requires

PS-09 requires you to document security and privacy responsibilities directly inside every organizational position description. Without defined roles in job descriptions, accountability gaps form quickly, and no one owns the security tasks that fall between teams.

The control targets a structural problem that most organizations overlook. Position descriptions are where role-based expectations become enforceable. When security and privacy duties aren’t written into them, training programs lose their anchor, audit evidence thins out, and employees can reasonably claim they didn’t know certain responsibilities were theirs. The NIST SP 800-53 framework treats this control as foundational across all three baselines. It underpins every other control in the personnel security family.

In practice, this means every role that interacts with organizational systems or data should have explicit language covering what security and privacy obligations the position carries. That language feeds directly into role-based training requirements, performance evaluations, and separation-of-duty enforcement. The official supplemental guidance emphasizes that specifying these roles in position descriptions creates clarity around training requirements, ensuring employees receive instruction matched to the actual duties they perform.

Why it matters

Organizations that skip embedding security duties into position descriptions create a governance gap that auditors flag consistently. The problem isn’t hypothetical risk from attackers. The problem is that without documented role expectations, you can’t demonstrate that employees understand their security obligations, and you can’t prove that training was aligned to actual job functions.

Failure to maintain this control introduces audit risk and may result in certification withdrawal or regulatory findings. Federal agencies and contractors face particular scrutiny here because assessors verify that position descriptions match the security responsibilities outlined in system security plans. When an assessor finds a disconnect between a system security plan and the actual duties documented for a role, the gap becomes a finding that affects the entire authorization package.

The absence of formalized role definitions also weakens your ability to enforce least privilege and separation of duties. If a position description doesn’t specify what systems or data a role should access, there’s no documented basis for restricting or reviewing that access. Over time, this leads to privilege creep that no periodic access review can catch because there’s no baseline to compare against.

Beyond compliance, vague position descriptions make it harder to hire the right people, train them effectively, and hold them accountable when security practices break down. Developing a strong security culture depends on employees understanding exactly what security responsibilities belong to them. When those responsibilities exist only as informal expectations, they erode the moment workload pressure increases or personnel turn over.

What auditors look for

  • Position descriptions that explicitly reference security and privacy roles, not generic “other duties as assigned” language
  • Alignment between documented position responsibilities and the security training each role receives
  • Evidence that position descriptions are reviewed and updated when roles change or new systems are introduced
  • Consistency between position descriptions and the access privileges granted to each role
  • Documentation showing that both security and privacy responsibilities are addressed separately where required

How to implement

Most organizations already have position descriptions on file, but retrofitting them with meaningful security and privacy language requires coordination between HR, security leadership, and system owners. The challenge isn’t creating the documents. It’s making the security content specific enough to be useful for training, access control, and audit evidence.

For your organization

Start by inventorying every position description that touches organizational systems, data, or physical spaces where sensitive information is processed. You need a complete list before you can identify gaps.

Map each role to its corresponding security and privacy responsibilities. A CISO or security program manager should define what security functions each role performs. Privacy officers should do the same for privacy-specific duties. These responsibilities should reference specific activities, not vague categories. “Reviewing access logs weekly” is actionable. “Supporting security initiatives” is not.

Use a recognized workforce framework to standardize how you describe security roles. The NICE cybersecurity workforce framework provides a taxonomy of work roles, tasks, and knowledge areas that you can map directly into position descriptions.

Integrate position descriptions into your role-based training program. When a position description specifies that a role includes incident reporting responsibilities, the training plan for that role should cover incident reporting procedures. This alignment is what auditors verify.

Review position descriptions on a defined schedule, typically annually or whenever a role’s system access or organizational responsibilities change. Document each review, including who conducted the review and what changed. Maintain version history so that assessors can trace how responsibilities evolved alongside system changes or organizational restructuring.

Establish a clear ownership model for each position description. HR typically owns the document format and lifecycle, but security and privacy teams must own the security content within it. Without that split ownership, security language tends to become stale or generic because HR staff don’t have the context to keep it current.

Common mistakes to avoid:

  • Copying identical security language into every position description regardless of role
  • Listing security responsibilities without connecting them to specific systems or data types
  • Failing to update position descriptions when roles are restructured or new systems are deployed
  • Treating position descriptions as HR-only documents that security teams never review

For your vendors

When assessing third-party compliance with PS-09, you need to verify that your vendors have formalized security and privacy roles within their own workforce. Self-attestation alone isn’t sufficient.

Questionnaire questions to include:

  • Do your position descriptions include specific security and privacy responsibilities for each role?
  • How frequently are position descriptions reviewed and updated to reflect changes in security requirements?
  • Can you provide redacted examples of position descriptions for roles with significant security responsibilities?
  • How do you align role-based security training with the duties specified in position descriptions?

Evidence to request:

  • Redacted samples of position descriptions for security-sensitive roles, showing embedded security and privacy language
  • Documentation of the review cadence for position descriptions
  • Records mapping position description responsibilities to training curricula
  • Organizational charts showing reporting lines for security and privacy functions

Red flags during assessment:

  • Vendors who cannot produce position descriptions with any security-specific language
  • Generic position descriptions that use identical security language across all roles
  • No documented review process or no evidence of recent updates
  • Inability to demonstrate how position descriptions connect to access control decisions or training plans

Verification beyond self-attestation:

Request actual document samples rather than accepting policy statements. Compare the security responsibilities listed in position descriptions against the vendor’s system security plan to check for consistency. Ask follow-up questions about how new hires in security-sensitive roles are onboarded using their position descriptions. Cross-reference the vendor’s organizational chart with the position descriptions they provide to verify that security responsibilities are distributed across roles rather than concentrated in a single individual with no backup coverage.

Evidence examples

Evidence TypeExample Artifact
Personnel security policyPersonnel Security Policy defining requirements for incorporating security and privacy roles into all organizational position descriptions
Position description samplesPosition descriptions for security-sensitive roles specifying security responsibilities, privacy obligations, and role-based training requirements
Security and privacy plansSystem security plan and privacy program plan documenting how position responsibilities align with security controls and privacy requirements
Review and update recordsRecords showing the review cadence for position descriptions, including reviewer identity, review date, and changes made
Role-to-training mappingDocumentation linking each position description’s security responsibilities to specific role-based training modules
Procedures documentationPersonnel security procedures describing the process for creating, reviewing, and updating position descriptions with security and privacy content

Cross-framework mapping

FrameworkControl(s)Coverage
ISO 27001:20225.2 Information security roles and responsibilitiesPartial

No related controls are referenced in the NIST SP 800-53 catalog for PS-09.

Frequently asked questions

What is NIST SP 800-53 PS-09

PS-09 is the NIST SP 800-53 control that requires organizations to incorporate security and privacy roles and responsibilities into their position descriptions. This control ensures that every organizational role with access to systems or data has documented, enforceable security obligations tied to that position. It applies across all three baselines (LOW, MODERATE, and HIGH) and provides the foundation for role-based security training and access control decisions.

What happens if PS-09 is not implemented

Without PS-09 implementation, your organization cannot demonstrate that employees understand their security and privacy responsibilities, which creates a direct audit finding. Assessors will flag the absence of security language in position descriptions as a gap, and this finding can affect certification outcomes for federal systems. The downstream impact extends to role-based training programs, which lose their documented basis when position descriptions don’t specify what security duties each role carries.

How do you audit PS-09

Auditing PS-09 starts with sampling position descriptions across multiple organizational roles and verifying that each one includes specific security and privacy responsibilities. Assessors check two objectives. First, that security roles are incorporated into position descriptions. Second, that privacy roles are incorporated separately. They then compare the documented responsibilities against the organization’s system security plan and privacy plan to confirm alignment, and they review evidence that position descriptions are updated on a defined schedule.

What security responsibilities should be in a job description

Every position description should include the specific security and privacy duties that the role performs, stated in actionable terms tied to systems, data types, or processes. For security-sensitive roles, this means documenting responsibilities such as access review participation, incident reporting obligations, data handling requirements, and any role-based training the position requires. The language should be precise enough that an assessor can map each responsibility to a corresponding training module or access control decision.

Experience superior visibility and a simpler approach to cyber risk management